2 ms·
I feel like it's quoted from somewhere else, but the reference escapes me. At any rate, it's a great quote. People who try the iterated design approach are esp
by ReidZB 13y ago
I feel like it's quoted from somewhere else, but the reference escapes me. At any rate, it's a great quote.
People who try the iterated design approach are especially frustrating. It ends up becoming a game of whack-a-mole with vulnerabilities, wherein an experienced cryptanalyst will point out an issue, the designer will say "oh! of course! let me apply a patch!", and then this continues to infinity. (This scenario doesn't necessarily indicate a bad approach, but it's certainly a symptom of iterated design.)
There's a particularly lovely story in Schneier's "Memo to the Amateur Cipher Designer" [1]:
> A cryptographer friend tells the story of an amateur who kept bothering him with the cipher he invented. The cryptographer would break the cipher, the amateur would make a change to "fix" it, and the cryptographer would break it again. This exchange went on a few times until the cryptographer became fed up. When the amateur visited him to hear what the cryptographer thought, the cryptographer put three envelopes face down on the table. "In each of these envelopes is an attack against your cipher. Take one and read it. Don't come back until you've discovered the other two attacks." The amateur was never heard from again.
Part of what makes it so frustrating, though, is that usually we want to be genuinely helpful. Building cryptosystems is fun (dangerously so!), and it's really crappy to end up saying "just scrap the whole thing" or what have you. But if you want to keep your sanity...
[1] https://www.schneier.com/crypto-gram-9810.html#cipherdesign https://www.schneier.com/crypto-gram-9810.html#cipherdesign